Security researchers reported that flaws in the UMANG portal, a platform that aggregates hundreds of Union and state public services, exposed user data across several databases. The alleged exposure matters because the portal is part of India’s digital public-service delivery ecosystem and involves sensitive personal and financial information.

The reported data included Provident Fund Universal Account Number (PF UAN) numbers, LPG booking details from an oil marketing company, and Aadhaar numbers stored in plain text across some services. The researchers said the weaknesses appeared architectural and may have existed for years.